Filtered by vendor Hcltech
Subscriptions
Total
193 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-27762 | 1 Hcltech | 1 Bigfix Platform | 2024-11-21 | 4.7 Medium |
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses | ||||
CVE-2021-27761 | 1 Hcltech | 1 Bigfix Platform | 2024-11-21 | 4.8 Medium |
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks | ||||
CVE-2021-27760 | 1 Hcltech | 1 Hcl Inotes | 2024-11-21 | 4.6 Medium |
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code. | ||||
CVE-2021-27759 | 1 Hcltech | 1 Bigfix Inventory | 2024-11-21 | 2.3 Low |
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application. | ||||
CVE-2021-27758 | 1 Hcltech | 1 Bigfix Inventory | 2024-11-21 | 4.3 Medium |
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account. | ||||
CVE-2021-27757 | 1 Hcltech | 1 Bigfix Insights | 2024-11-21 | 7.5 High |
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information." | ||||
CVE-2021-27756 | 1 Hcltech | 1 Bigfix Compliance | 2024-11-21 | 7.5 High |
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it." | ||||
CVE-2021-27755 | 1 Hcltech | 1 Hcl Sametime | 2024-11-21 | 5.5 Medium |
"Sametime Android potential path traversal vulnerability when using File class" | ||||
CVE-2021-27753 | 1 Hcltech | 1 Hcl Sametime | 2024-11-21 | 5.5 Medium |
"Sametime Android PathTraversal Vulnerability" | ||||
CVE-2020-4129 | 1 Hcltech | 1 Hcl Domino | 2024-11-21 | 5.3 Medium |
HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the LDAP service. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later. | ||||
CVE-2020-4128 | 1 Hcltech | 1 Domino | 2024-11-21 | 5.3 Medium |
HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service. | ||||
CVE-2020-4127 | 1 Hcltech | 1 Hcl Domino | 2024-11-21 | 6.5 Medium |
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later. | ||||
CVE-2020-4126 | 1 Hcltech | 1 Hcl Inotes | 2024-11-21 | 5.9 Medium |
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later. | ||||
CVE-2020-4107 | 1 Hcltech | 1 Domino | 2024-11-21 | 8.8 High |
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure. | ||||
CVE-2020-4104 | 1 Hcltech | 1 Bigfix Webui | 2024-11-21 | 5.4 Medium |
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a. | ||||
CVE-2020-4102 | 1 Hcltech | 1 Notes | 2024-11-21 | 6.7 Medium |
HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system. | ||||
CVE-2020-4101 | 1 Hcltech | 1 Hcl Digital Experience | 2024-11-21 | 9.8 Critical |
"HCL Digital Experience is susceptible to Server Side Request Forgery." | ||||
CVE-2020-4099 | 1 Hcltech | 1 Verse | 2024-11-21 | 5.9 Medium |
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app. | ||||
CVE-2020-4097 | 1 Hcltech | 1 Notes | 2024-11-21 | 6.8 Medium |
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client. | ||||
CVE-2020-4095 | 1 Hcltech | 1 Bigfix Platform | 2024-11-21 | 6.0 Medium |
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access." |